> Except for the first feature, you need to explicitly configure
> and regularly maintain a squid cache to keep getting security
> benefits from it.

So, based upon your comments, simply requiring a squid reverse-proxy
offers no _real_ benefit (excluding caching, which is of little help in
this case) over a standard firewall, unless you explicitely create
rules/acls to limit access to just what the webserver behind the proxy
